Trojan

How to remove “Trojan:Win32/Esulat”?

Malware Removal

The Trojan:Win32/Esulat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Esulat virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Esulat?


File Info:

name: 9C3396AA940839162272.mlw
path: /opt/CAPEv2/storage/binaries/c6c332ae1ccb580ac621d3cf667ce9c017be41f8ad04a94c0c0ea37c4789dd14
crc32: 749DF9B0
md5: 9c3396aa94083916227201bf1396a2ca
sha1: 02133960eeb5dbf136e37d1b1b317306eae85036
sha256: c6c332ae1ccb580ac621d3cf667ce9c017be41f8ad04a94c0c0ea37c4789dd14
sha512: 6398b2c6f049c5cab2cf423c45f2d24fa07c40261697f4de44d12f3910d97ea0c1861c7fc121c8ac85e63a2488c5f462e07e370114f052424e68ac08d35a38f9
ssdeep: 12288:X/aUsuYachgVK4jwvei6o+93Idh5FsljraoB+rJi4m29zKpRtbPEM5uaY6u/:vaUxvxK4jwFk3If5FsZrTBgihLto//
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D615BFCD71E0422EC6270A3648B6C134E7FAED115651F1C9E7E1FA2736336A5860B2BD
sha3_384: 95a51e8902dfac9e96c3a1c42019b81997c6ec2861858beed490fc8e6500153a6b86e70242b14e346a8288d150bc9a13
ep_bytes: e85c640000e978feffff8bff558bec56
timestamp: 2014-08-27 16:40:54

Version Info:

0: [No Data]

Trojan:Win32/Esulat also known as:

BkavW32.AIDetectMalware
LionicTrojan.Script.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.61361577
FireEyeGeneric.mg.9c3396aa94083916
SkyhighBehavesLike.Win32.Infected.dh
McAfeeGeneric .qh
MalwarebytesMalware.AI.3934434827
VIPRETrojan.GenericKD.61361577
SangforTrojan.Win32.Agent.Vd77
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Script/SLoad.6c5dd50c
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D3A84DA9
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
CynetMalicious (score: 99)
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.61361577
AvastWin32:Malware-gen
TencentScript.Trojan.Generic.Azlw
SophosMal/Generic-S
F-SecureMalware.JS/Agent.bvoew
DrWebTrojan.MulDrop21.13639
TrendMicroPossible_SCRDL
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.61361577 (B)
IkarusTrojan.Win32.Casdet
WebrootW32.Trojan.Gen
VaristJS/Agent.SU!Eldorado
AviraJS/Agent.bvoew
MAXmalware (ai score=100)
Antiy-AVLTrojan[APT]/Win32.Sectora05
Kingsoftmalware.kb.a.987
XcitiumMalware@#17fewnfs0t2xl
MicrosoftTrojan:Win32/Esulat
ViRobotTrojan.Win32.S.Agent.956340
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.61361577
GoogleDetected
AhnLab-V3Dropper/Win32.Agent.C2916249
ALYacTrojan.Agent.956340B
TACHYONTrojan/W32.Agent.956340
Cylanceunsafe
PandaTrj/CI.A
RisingDownloader.Agent/JS!8.10EAD (TOPIS:E0:YAzHGr5jP9E)
YandexHTML.Psyme.Gen
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Script.A!tr.dldr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Esulat?

Trojan:Win32/Esulat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment